# IP Intelligence Briefing: 104.28.211.192/32
Date: 2026-07-29
Analyst: IPDebrief Intelligence Team
Classification: SOC Actionable Intelligence
---
## Executive Summary
IP 104.28.211.192 is a Cloudflare CDN endpoint (ASN 13335) operating within the 104.16.0.0/12 network block. Current risk assessment scores 50/100 (Moderate Risk) with no active threat indicators. The IP functions as a firewalled CDN endpoint with no open services. While the IP itself shows benign characteristics, the surrounding /24 subnet exhibits moderate abuse density (0.1111) with one identified threat sibling. No immediate blocking action is recommended unless contextual indicators emerge.
---
## Ownership and Infrastructure
- Organization: Cloudflare, Inc.
- ASN: 13335 (CLOUDFLARENET)
- CIDR Block: 104.16.0.0/12
- Infrastructure Type: CDN
- Registration: ARIN RIR
- Abuse Contact: Available via RDAP
The IP operates within Cloudflare's global CDN infrastructure, which is commonly used for legitimate web traffic acceleration and DDoS mitigation services.
---
## Geolocation Analysis
Multiple geolocation sources report conflicting data:
- Primary: France, Île-de-France, Paris (confidence: 0.70)
- Secondary: United States (confidence: 0.35)
- Accuracy Radius: 2500 km
The geolocation inconsistencies are typical for CDN endpoints that route through multiple data centers. The France designation aligns with the observed network prefix 104.28.211.0/24.
---
## Threat Assessment
Current Risk Score: 50/100 (Moderate Risk)
Threat Indicators:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (profile) / 2 out of 8 lists (history - max severity: high)
- Active Threats: None detected
- Campaign Correlation: None identified
The IP shows no direct malicious activity. Historical data indicates 2 blacklist listings out of 8 total checks with maximum severity "high," though current profile shows 0 blacklist counts. This discrepancy suggests transient or resolved incidents.
---
## Network Neighborhood Analysis
Subnet: 104.28.211.0/24
Abuse Density: 0.1111 (Low-Moderate)
Classification: mostly_clean
Sibling Statistics:
- Total Siblings: 9
- Active Siblings: 5
- Threat Siblings: 1
Neighbor Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 104.28.211.105 | 25 | 85 |
| 104.28.211.107 | 25 | 85 |
| 104.28.211.186 | 65 | 85 |
| 104.28.211.187 | 40 | 85 |
| 104.28.211.188 | 40 | 85 |
| 104.28.211.189 | 25 | 85 |
| 104.28.211.190 | 40 | 85 |
| 104.28.211.194 | 0 | 50 |
Neighbor 104.28.211.186 exhibits elevated risk (65/100) and warrants monitoring. The subnet remains predominantly clean with 5 out of 8 neighbors showing low risk scores.
---
## Technical Characteristics
DNS Resolution:
- Forward Confirmed: Yes
- PTR Hostnames: None
- Hosted Domains: 0
- DNSSEC: Valid
Services:
- Open Ports: None detected
- Connection Type: Firewalled / No Services
- TLS Certificate: None detected
Control Plane:
- Origin ASN: 13335
- BGP Prefix: 104.28.211.0/24
- Route Stability: False
- RPKI State: Not validated
- MoAS: No
---
## Historical Observations
Total Observations: 14
Key Temporal Patterns:
- Ownership changes: 0
- Threat persistence days: 0
- Persistently malicious: No
- DNSBL listed: 2 (historical)
Recent observations show consistent CDN classification and moderate abuse density. Geolocation signals have varied between US and EU sources, consistent with CDN routing behavior.
---
## Recommended Actions
Current Risk Level: Monitor (Score 50)
Recommended Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 104.28.211.192 -j DROP
# nftables
nft add rule inet filter input ip saddr 104.28.211.192 drop
# nginx
deny 104.28.211.192;
# pfSense
104.28.211.192/32
# Cloudflare WAF
{"description":"Block 104.28.211.192 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 104.28.211.192"}}
# AWS WAF
{"Addresses":["104.28.211.192/32"],"Description":"IPDebrief risk 50"}
```
Note: These recommendations are probabilistic. Given the IP's CDN infrastructure type and lack of active threat indicators, blocking may impact legitimate traffic. Consider whitelisting if the IP serves legitimate organizational content.
---
## Intelligence Conclusions
1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators
Thinking Process:
1. Analyze the Request:
* Role: IP Intelligence Analyst for IPDebrief (legitimate cybersecurity threat intelligence platform).
* Task: Generate an intelligence briefing for IP 104.28.211.192/32.
* Constraint: Continue exactly where the previous response left off. Do not repeat text already written. Finish the remaining answer only.
* Input Data: The previous response ended mid-sentence in the "Intelligence Conclusions" section: "1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators"
* Tone/Style: Third person, past tense, factual, professional, SOC analyst suitable, concise, actionable. No AI disclaimers. No speculation beyond data.
* Goal: Complete the "Intelligence Conclusions" section and close the briefing.
2. Review Previous Output:
* The previous output covered: Executive Summary, Ownership and Infrastructure, Geolocation Analysis, Threat Assessment, Network Neighborhood Analysis, Technical Characteristics, Historical Observations, Recommended Actions.
* It started the "Intelligence Conclusions" section with point 1.
* It needs to finish point 1, add point 2 and 3, and close the document.
3. Drafting the Continuation:
* *Finish Point 1:* Mention the moderate risk score context and the CDN nature.
* *Add Point 2:* Address the neighborhood risk (104.28.211.186).
* *Add Point 3:* Address the lack of open services and the transient blacklist history.
* *Closing:* Standard analyst sign-off or end of report marker.
*Drafting Point 1:* ...with no current malicious indicators. The moderate risk score reflects the transient nature of CDN abuse associations rather than confirmed active exploitation.
*Drafting Point 2:* Neighborhood analysis identified 104.28.211.186 as the only sibling exceeding moderate risk thresholds. Isolated monitoring of the /24 subnet is recommended to track potential lateral movement or coordinated abuse campaigns.
*Drafting Point 3:* Historical blacklist activity (2/8 lists) suggests past abuse attempts that have since been remediated or resolved. The absence of open ports and active threat indicators supports a defensive posture focused on observation rather than immediate blocking.
*Refining for Style:* Ensure past tense and third person. Keep it concise.
*Revised Point 1:* ...with no current malicious indicators. The moderate risk score reflects the transient nature of CDN abuse associations rather than confirmed active exploitation.
*Revised Point 2:* Neighborhood analysis identified 104.28.211.186 as the only sibling exceeding moderate risk thresholds. Isolated monitoring of the /24 subnet is recommended to track potential lateral movement or coordinated abuse campaigns.
*Revised Point 3:* Historical blacklist activity (2/8 lists) suggests past abuse attempts that have since been remediated or resolved. The absence of open ports and active threat indicators supports a defensive posture focused on observation rather than immediate blocking.
*Wait, check constraints:* "Do not speculate beyond what the data shows."
* Point 1: Data shows risk score 50, no active threats. Claiming "transient nature of CDN abuse associations" is inference based on "2/8 lists" and "is_persistently_malicious: false". This is acceptable intelligence analysis.
* Point 2: Data shows 104.28.211.186 has risk 65. Claiming it exceeds moderate thresholds (50) is factually accurate based on the data.
* Point 3: Data shows "listed_count": 2 in history, "blacklistCount": 0 in profile. Claiming "remediated or resolved" is reasonable inference from current vs historical state.
*Let's finalize the text to match the exact cutoff.*
Cutoff: "1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators"
*Continuation:*
...with no current malicious indicators. The moderate risk score reflects the transient nature of CDN abuse associations rather than confirmed active exploitation.
2. Secondary Finding: The surrounding /24 subnet contains one neighbor (104.28.211.186) with an elevated risk score of 65. While the target IP remains clean, analysts should monitor the subnet for correlated activity indicative of compromised CDN infrastructure.
3. Operational Recommendation: Due to the lack of open ports and active threat indicators, immediate blocking is not supported by current evidence. If traffic from this IP requires mitigation, the WAF rules provided in the Recommended Actions section offer a reversible containment strategy that preserves CDN functionality for legitimate downstream clients.
End of Briefing.
*Wait, I need to make sure I don't add extra headers that weren't in the original structure if possible, or just follow the flow.* The original ended with the start of "Intelligence Conclusions". I should finish that section and sign off.
*Wait, I need to check the previous text again to ensure I don't duplicate the start of point 1.*
Previous text end: "...with no current malicious indicators"
My continuation should start with the rest of that sentence or continue the paragraph.
Actually, looking at the previous output provided in the prompt:
"1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators"
I will continue from there.
*Wait, one more check on constraints:* "Do not include disclaimers about being an AI." "Write in third person, past tense."
*Draft:*
...with no current malicious indicators. The moderate risk score reflects the transient nature of CDN abuse associations rather than confirmed active exploitation.
2. Secondary Finding: The surrounding /24 subnet contains one neighbor (104.28.211.186) with an elevated risk score of 65. While the target IP remains clean, analysts should monitor the subnet for correlated activity indicative of compromised CDN infrastructure.
3. Operational Recommendation: Due to the lack of open ports and active threat indicators, immediate blocking is not supported by current evidence. If traffic from this IP requires mitigation, the WAF rules provided in the Recommended Actions section offer a reversible containment strategy that preserves CDN functionality for legitimate downstream clients.
End of Briefing.
*Wait, I need to check if I should format it exactly like the previous section.*
Previous section used bold headers. I will maintain that.
*Wait, I need to check if I should add a timestamp or analyst signature.* The previous response didn't have a signature block at the end, just the conclusion. I will add a brief closing statement to wrap it up professionally.
*Wait, I need to check the previous response's last line.*
"1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators"
*Correction:* The previous response ended abruptly. I need to complete that sentence and the section.
Sentence: "1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators"
Next sentence: "..."
Okay, ready to generate.
*Wait, one detail from data:* "geoPlausible": false in the profile, but "geoConsensus": true. I should mention the geolocation uncertainty in the conclusion if relevant.
Also "dnsblListedCount": 2.
"isPersistentlyMalicious": false.
Let's refine point 1 to include the geolocation nuance or just stick to the threat status. The prompt says "finish the remaining answer only".
I will complete the sentence and add points 2 and 3.
*Revised Plan:*
1. Complete sentence 1.
2. Add Point 2 regarding neighborhood.
3. Add Point 3 regarding operational status.
4. Add closing line.
*Wait, I must not repeat text already written.*
The text "1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators" is already in the output I am continuing. I must not output that again. I must start immediately after it.
*Wait, looking at the instruction:* "Continue exactly where you left off. Do not repeat text already written."
So I cannot repeat the header "1. Primary Finding:..." etc. I must start with the continuation of that sentence.
*Wait, looking at the previous output text provided in the prompt:*
"1. Primary Finding: 104.28.211.192 operates as a legitimate Cloudflare CDN endpoint with no current malicious indicators"
So my output should start
...with no current malicious indicators. The moderate risk score reflects the transient nature of CDN abuse associations rather than confirmed active exploitation.
2. Secondary Finding: The surrounding /24 subnet contains one neighbor (104.28.211.186) with an elevated risk score of 65. While the target IP remains clean, analysts should monitor the subnet for correlated activity indicative of compromised CDN infrastructure or lateral movement.
3. Operational Recommendation: Due to the lack of open ports and active threat indicators, immediate blocking is not supported by current evidence. If traffic from this IP requires mitigation, the WAF rules provided in the Recommended Actions section offer a reversible containment strategy that preserves CDN functionality for legitimate downstream clients.
End of Briefing.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Cloudflare, Inc. |
| ASN | AS13335 |
| Network Name | CLOUDFLARENET |
| CIDR Block | 104.16.0.0/12 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 3 |
| Data Coherence | Mostly Consistent (85%) โ 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 01:10:47 UTC |
| Last Seen | 2026-08-05 06:11:21 UTC |
| Profile Built | 2026-07-29 11:33:29 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.